Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.
If you cannot find an answer then contact us or click the chat button on the lower right..
-
Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
-
CMMC Fundamentals
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
SPRS & Self-Assessment
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
-
Artificial Intelligence (AI)
Flowdown: Which Clauses You Must Pass to Your Subcontractors
DFARS flowdown requirements are where most real compliance exposure sits, and where the fewest contractors have a defensible position. The obligation runs both directions — you inherit requirements from your prime and you owe them to your suppliers — and a gap anywhere in that chain lands on whoever the government is contracting with. For how the individual clauses work, start with DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires.
Two mistakes dominate. The first is under-flowing: never passing the clause to a supplier who genuinely handles the data. The second is over-flowing: papering every vendor in the building with 7012, including the landscaping company. Both create risk. Only one of them creates work.
Which clauses flow down
| Clause | Flows down? | To whom |
|---|---|---|
| FAR 52.204-21 | Yes, all tiers | Subs whose systems will have FCI |
| DFARS 252.204-7012 | Yes | Subs whose performance involves covered defense information |
| DFARS 252.204-7019 | No | Notice clause to offerors — but see 7020 |
| DFARS 252.204-7020 | Yes | Subs handling CUI — plus a verification duty on you |
| DFARS 252.204-7021 | Yes | Subs where a CMMC level applies |
Note the condition attached to each. Flowdown is triggered by data, not by supplier status. The clause does not follow the subcontract; it follows the covered information.
The verification duty most primes miss
This is the single most commonly missed obligation in the whole category, so it gets its own section.
DFARS 252.204-7020 does not just require you to flow the clause down. It requires you to ensure that a subcontractor handling CUI has a current NIST SP 800-171 assessment posted in SPRS before you award the subcontract.
That is an active check. Putting the clause in the terms and conditions does not satisfy it. Requiring the supplier to represent that they’ve done it does not satisfy it. You have to confirm the score is actually there.
Most primes we see have flowed the clause perfectly and never looked at a single supplier’s score. That is a real gap, it’s discoverable in an assessment, and it’s a two-minute fix per supplier once someone owns it. See DFARS 252.204-7019 vs 7020 vs 7021 for the underlying clause mechanics.
The decision tree
Run this per supplier. It takes about a minute each once you know your own data flows.
Question 1: Will this supplier’s people or systems touch Federal Contract Information?
If no — no cybersecurity clause flows. A supplier who never sees anything you generated for the government doesn’t need one. Your office cleaning contractor, your commercial landlord, the company that services the HVAC.
If yes — flow FAR 52.204-21 and the 15 basic safeguarding requirements, and continue to question 2.
Question 2: Will they process, store, or transmit covered defense information?
If no — stop at FAR 52.204-21. This is the population most contractors over-serve.
If yes — flow 7012 and 7020, verify their SPRS score exists and is current, and continue to question 3.
Question 3: Does your contract designate a CMMC level, and does their work fall within it?
If yes — flow 7021 as well, and check whether your prime’s own flowdown language imposes anything beyond what DoD currently requires.
Question 4: Will they operate inside your environment?
Different question, and it’s the one with the sharpest consequences. Covered below.
External Service Providers: the flowdown that isn’t a flowdown
A supplier who operates part of your environment — your MSP, a managed security vendor, whoever runs your enclave — is not just a recipient of flowdown clauses. They become an External Service Provider and appear in your assessment boundary description.
That means an assessor will look at what they do, how the responsibilities split, and whether anything falls between the two firms. “Our MSP handles that” is not an answer to an assessment finding.
Every co-delivery relationship needs a written responsibility split covering, at minimum:
- Who owns security configuration, and who has enforcement authority
- Who owns hardware and end-user support
- How gaps get reported between the firms
- What happens when a reported gap goes unremediated
Get that in writing at the start. Discovering during an assessment that both firms assumed the other owned patching is a bad afternoon. Vendor and partner selection covers what to look for before you sign.
What flows the other way: what your prime owes you
Flowdown is usually discussed downward, but the upward view matters as much.
Your prime should tell you what data you’ll actually receive, and whether it’s FCI or CUI. Many don’t, and many subs discover mid-performance that they’ve been receiving controlled technical information they weren’t scoped for.
Ask before award, in writing. The question is: what specific information will we receive, and is any of it CUI? If the prime can’t answer, that’s information too — and it’s a question your own contracting officer can help settle.
Watch for the reverse problem as well: primes who flow down requirements that exceed what the contract obliges. This happens more since the CMMC suspension, because a prime managing its own liability may keep certification language regardless of what DoD paused. That’s within their rights. It’s also negotiable, and worth negotiating before you sign rather than after.
What the CMMC suspension changed
For flowdown specifically: less than people hoped.
The July 2026 suspension binds DoD, not primes. DFARS 252.204-7021 still requires primes to flow down the substance of CMMC requirements, and a prime is entirely free to keep certification language in subcontract terms.
So relief does not flow downhill automatically. If someone at a prime has told you verbally that requirements are relaxed, get it in writing before you change your assessment plans. A program manager’s reassurance is not a contract modification, and it will not help you if the flowdown language is still in the subcontract you signed.
Meanwhile 7012 and 7020 flowdown obligations were untouched. What DFARS 252.204-7012 requires still flows, the verification duty still applies, and DIBCAC can still assess.
A practical way to get current
Most contractors have never run this exercise. It takes an afternoon and it surfaces things.
- List every supplier who touches anything you produce for or receive from the government. Include software vendors and anyone with remote access.
- Mark each one FCI, CUI, or neither. If you can’t tell, that’s a scoping problem, not a flowdown problem — fix it first.
- Check what you actually flowed down to each. Pull the subcontract, don’t rely on the template you think you use.
- For every CUI supplier, look up their SPRS score. This is the verification duty. Do it now rather than when someone asks.
- For every supplier inside your environment, find the responsibility split. If there isn’t one in writing, that’s the first thing to fix.
A new subcontract, a new prime relationship, or a supplier change are all trigger events that should restart this review. Annual is not often enough if your supply base moves.
Common questions about DFARS flowdown requirements
Which DFARS clauses must be flowed down to subcontractors?
DFARS 252.204-7012, 7020, and 7021 flow down, as does FAR 52.204-21 where Federal Contract Information is involved. DFARS 252.204-7019 is a notice clause to offerors and does not flow down, though the verification duty in 7020 covers similar ground. Each flows only to subcontractors whose performance involves the covered information.
Do I have to verify my subcontractor’s SPRS score?
Yes. DFARS 252.204-7020 requires you to ensure a subcontractor handling CUI has a current NIST SP 800-171 assessment posted in SPRS before awarding the subcontract. This is an active verification duty — including the clause in your terms does not satisfy it.
Does every supplier need DFARS 252.204-7012 in their subcontract?
No. The clause flows down only to subcontractors whose performance involves covered defense information. A supplier who never touches CUI does not need the CUI clause. Applying it universally creates administrative work without reducing risk, and it can complicate supplier relationships unnecessarily.
Does the CMMC suspension remove prime contractor flowdown requirements?
No. The July 2026 suspension binds DoD, not primes. A prime managing its own liability may keep certification language in subcontract terms regardless. Any change to your flowdown obligations should be confirmed in writing before you alter your assessment plans.
What is an External Service Provider in a CMMC assessment?
A supplier that operates part of your environment on your behalf — a managed IT provider, a managed security vendor, or an enclave operator. They appear in your assessment boundary description, and the split of responsibilities between the two firms should be documented in writing, covering security configuration authority, hardware and end-user support, gap reporting, and unremediated findings.
Next step: Step two of the exercise above — marking each supplier FCI, CUI, or neither — is the one that stalls people, because it depends on knowing your own boundary first. The CUI Scoping Workbook is a fillable 15-page workbook for defining the smallest defensible boundary. Free, no email required.
Last reviewed: August 2026. CMMC program status is under review; verify current requirements against official sources before acting.